Skip to main content

Vendor/product archive

ibm / lotus_notes CVEs

Beta · best-effort

72 CVEs tagged to ibm / lotus_notes35 Critical, 12 High, 21 Medium, 4 Low, 0 Unrated.

CVE-2013-0522

Published Jul 16, 2018

The Notes Client Single Logon feature in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3, and 9.0 on Windows allows local users to discover passwords via vectors involving a…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2012-6349

Published Jul 18, 2013

Buffer overflow in the .mdb parser in Autonomy KeyView IDOL, as used in IBM Notes 8.5.x before 8.5.3 FP4, allows remote attackers to execute arbitrary code via a crafted file, aka…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0538

Published May 1, 2013

Cross-site scripting (XSS) vulnerability in IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1 allows remote attackers to inject arbitrary web script…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0127

Published May 1, 2013

IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1 does not block APPLET elements in HTML e-mail, which allows remote attackers to bypass intended res…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4846

Published Dec 19, 2012

IBM Lotus Notes 8.5.x before 8.5.3 FP3 does not include the HTTPOnly flag in a Set-Cookie header for a web-application cookie, which makes it easier for remote attackers to obtain…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5251

Published Sep 7, 2012

Multiple untrusted search path vulnerabilities in IBM Lotus Notes 8.5 allow local users to gain privileges via a Trojan horse (1) nnoteswc.dll or (2) nlsxbe.dll file in the curren…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2174

Published Jun 20, 2012

The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a crafted notes:// URL.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-1512

Published May 31, 2011

Heap-based buffer overflow in xlssr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a malformed BIFF re…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-1218

Published May 31, 2011

Buffer overflow in kvarcve.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted .zip attachment, a…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-1217

Published May 31, 2011

Buffer overflow in kpprzrdr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted .prz attachment.…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-1216

Published May 31, 2011

Stack-based buffer overflow in assr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via crafted tag data in…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-1215

Published May 31, 2011

Stack-based buffer overflow in mw8sr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted link in…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-1214

Published May 31, 2011

Stack-based buffer overflow in rtfsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted link in…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-1213

Published May 31, 2011

Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted header in a .lzh a…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0912

Published Feb 8, 2011

Argument injection vulnerability in IBM Lotus Notes 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP5 allows remote attackers to execute arbitrary code via a cai:// URL containing…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-1608

Published Apr 29, 2010

Stack-based buffer overflow in IBM Lotus Notes 8.5 and 8.5fp1, and possibly other versions, allows remote attackers to execute arbitrary code via unknown attack vectors, as demons…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 72 CVEsPage 1 of 3